Wednesday, February 8, 2006

block RFC-1918 by ipfw2

RFC-1918, the private block
these IP address should be stopped on the outside interface, except when they responses to traceroute and some type of ICMP.
${fwcmd} table 1 flush
${fwcmd} table 1 add
${fwcmd} table 1 add
${fwcmd} table 1 add
${fwcmd} add deny all from 'table(1)' to any in via ${oif}

